Privacy Policy
Last updated: July 29, 2026
This Privacy Policy explains how NanoCo, Inc. (“NanoCo”, “we”, “us”) handles information collected through nanoclaw.dev (the “Site”).
What this policy covers
This policy covers two things: the Site — the marketing pages, blog, and skill documentation you are reading right now — and the optional NanoClaw account service, used only to fetch the prebuilt hardened agent image, described under NanoClaw accounts and the hardened agent image.
It does not cover the NanoClaw software itself. NanoClaw is open-source software distributed under the MIT License from GitHub and runs on hardware you control. When you install and run NanoClaw, it talks to the model providers, messaging channels, and other services you configure it to use, with credentials you supply. We do not receive that data, and how those providers handle it is governed by their own privacy policies — not this one.
Information we collect
Information you choose to give us
The Site itself has no accounts, no sign-up, no contact forms, and no payments. You can read every page without submitting anything. If you email us, we receive your email address, your message, and anything you attach to it. If you create a NanoClaw account to fetch the hardened agent image, what we receive is described in the next section.
Information collected automatically
- Server request logs. The Site is hosted by Vercel. Like any web host, Vercel records requests to the Site, including your IP address, browser user-agent string, the URL requested, the referring page, and a timestamp. These logs are used to serve the Site and to keep it secure and available.
- Google Analytics. We use Google Analytics 4 (measurement ID
G-BM37FRD8EF) to understand which pages people find useful. It sets cookies and collects page views, approximate location derived from your IP address, device and browser type, and the source that referred you. - Vercel Analytics. We use Vercel’s privacy-friendly analytics for aggregate traffic counts. It does not set cookies and does not track you across sites; visitors are counted using a hash derived from request data rather than a persistent identifier.
- Google Fonts. The Site loads the Inter and JetBrains Mono typefaces from Google’s font servers. Your browser therefore makes a request to Google when a page loads, which exposes your IP address and user-agent to Google.
- Country-level routing. One page (
/scheduling-agent) reads the country code that Vercel derives from your IP address in order to decide where to send you. We do not store this value.
We do not run advertising, retargeting, or cross-site tracking pixels, and we do not build profiles of individual visitors.
NanoClaw accounts and the hardened agent image
NanoClaw runs without any account. One optional feature involves one: fetching the prebuilt hardened agent image from our hosted registry instead of building the image on your own machine. Building locally is the default and needs no sign-in; the account is there mainly so we can protect the registry from abuse. If you never sign in, this section does not apply to you.
This part of the service is new and still developing. The description below reflects how it works as of the “Last updated” date above; we will revise it as the service changes.
What we collect
- At sign-in: your verified email address and your identity-provider user id. The address is supplied by the identity provider you sign in with, rather than read from your machine, and it is the key your account is stored under. Signing in with two different addresses creates two separate accounts, which we have no way to merge today.
- At each image fetch: a timestamp, the image requested, and your IP address, which we currently truncate to a /24 network. The registry also keeps its own operational logs of pull activity.
What we do not collect
The account service is not designed to receive anything about your agents — groups, channels, messages, prompts, files, or API keys — and we do not want that data. NanoClaw does not report back to us once the image is on your machine, so in the ordinary course we know only that an image was fetched, not what you do with it afterwards.
Your email address and updates (opt-in)
During sign-in we ask, once per account, whether NanoClaw and Echo — the partner who builds the hardened image — may email you security notices and project updates. The default is no, an unanswered prompt is treated as a no, and declining does not affect your access. If you say yes, we store your answer together with the wording you were shown when you gave it. Marketing email includes an unsubscribe link, which is the quickest way to withdraw. We may still send you occasional service messages about your account or a security issue affecting the image.
The credential on your machine
The sign-in credential is stored locally under ~/.config/nanoclaw/ with owner-only file permissions, and
it is scoped to requesting short-lived, pull-only access to the image repository. Running the sign-in script with
--logout revokes it on our side and removes it from your machine. Keeping your own machine and account
secure remains your responsibility.
Cookies and similar technologies
The only cookies set by the Site are Google Analytics cookies:
| Cookie | Set by | Purpose | Typical lifetime |
|---|---|---|---|
_ga | Google Analytics | Distinguishes returning visitors | 2 years |
_ga_BM37FRD8EF | Google Analytics | Maintains analytics session state | 2 years |
You can decline or remove these at any time:
- Block or delete cookies in your browser settings.
- Install the Google Analytics Opt-out Browser Add-on.
- Use a content blocker — the Site works normally with analytics blocked.
How and why we use information
We use the information described above to:
- Serve the Site and deliver the pages you request.
- Measure which content is read so we can improve the documentation and posts.
- Diagnose errors, investigate abuse, and protect the Site’s availability and integrity.
- Operate the hardened-image registry: authenticate your pulls and protect the service from abuse.
- Send you security notices and project updates where you opted in, until you unsubscribe.
- Respond to you if you contact us.
- Comply with legal obligations.
If you are in the European Economic Area or the United Kingdom, our legal bases under the GDPR are: our legitimate interests in operating, securing, and improving the Site and the registry (server logs, cookieless analytics, abuse prevention, responding to your messages); performance of a contract when you create a NanoClaw account and fetch the hardened image; your consent where required for cookie-based analytics and for email updates, withdrawable at any time; and compliance with legal obligations where a law requires us to retain or disclose information.
Who we share information with
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We disclose information only to:
- Service providers that operate the Site on our behalf — currently Vercel (hosting, logs, analytics) and Google (Analytics, Fonts).
- Echo, the partner who builds the hardened agent image — your email address, where you opted in to email updates, so they can send the security notices and project updates you agreed to receive.
- Authorities or other parties where we believe in good faith that disclosure is required by law or necessary to protect the rights, safety, or property of NanoCo, our users, or the public.
- A successor entity in connection with a merger, acquisition, financing, or sale of assets. We will note any resulting change in this policy.
Third-party sites and communities
The Site links to places we do not control, including GitHub, Discord, X, YouTube, and nanoco.ai. Following those links takes you onto services with their own terms and privacy policies. Anything you post in our Discord server or in GitHub issues and discussions is public and governed by that platform’s policy, not this one.
How long we keep information
Server request logs are retained for a limited period by our hosting provider for security and operational purposes. Google Analytics data is retained according to the data-retention setting on our property, after which Google deletes user-level records. Email you send us is kept as long as needed to handle your request and to maintain a record of the correspondence. NanoClaw account records are kept while your account exists; image-fetch records are kept for a limited period for security and abuse prevention, and longer where a law or a live security investigation requires it. If you opt out of email updates, we keep a record of that choice so that we can honor it.
International data transfers
NanoCo is based in the United States, and our providers process data in the United States and other countries. If you access the Site from outside the United States, your information will be transferred to and processed there. Where transfers from the EEA, UK, or Switzerland require a safeguard, our providers rely on the European Commission’s Standard Contractual Clauses or another approved transfer mechanism.
Your privacy rights
Depending on where you live, you may have the right to access the personal information we hold about you, to have it corrected or deleted, to restrict or object to certain processing, to receive it in a portable format, and to withdraw consent you previously gave. Residents of California and other US states with comprehensive privacy laws additionally have the right to know what we collect, to request deletion or correction, to opt out of the sale or sharing of personal information (we do neither), and not to be discriminated against for exercising these rights.
To exercise any of these rights, email
privacy@nanoco.ai. You may use an authorized agent where the law allows it. For
email updates specifically, the fastest path is the unsubscribe link in any email we send; to remove the registry
credential from your machine and revoke it on our side, run the sign-in script with --logout.
One practical note, so there are no surprises: because the Site requires no account and we do not collect names or contact details, we usually have no way to connect analytics or log records to a specific person. Where we cannot reasonably verify that records relate to you, we will tell you rather than hand over someone else’s data.
If you are in the EEA or UK and believe we have mishandled your information, you may lodge a complaint with your local supervisory authority. We would appreciate the chance to address it first.
Do Not Track and Global Privacy Control
There is no common standard for how sites should respond to browser “Do Not Track” signals, and the Site does not currently respond to them. Because we do not sell or share personal information for advertising, a Global Privacy Control signal has no sale or sharing to opt out of. To stop analytics collection entirely, use one of the methods listed under Cookies and similar technologies.
Children’s privacy
The Site is intended for software developers and is not directed to children. We do not knowingly collect personal information from anyone under 13 (or under 16 in the EEA and UK). If you believe a child has provided us with personal information, contact us and we will delete it.
Security
The Site is served over HTTPS and is built as static pages, which keeps the amount of data it handles small by design. No method of transmission or storage is completely secure, so we cannot guarantee absolute security — but we also do not hold the kind of data that would make the Site an interesting target.
Changes to this policy
We may update this policy as the Site changes. When we do, we will revise the “Last updated” date at the top of this page. Material changes will be noted more prominently on the Site.
Contact us
Questions, requests, or complaints about privacy: privacy@nanoco.ai.
NanoCo, Inc.
nanoco.ai
See also our Terms of Service.